Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 70
No
1

Optimized hybrid CNN-LSTM-GRU model for cyber attack detection using Adaptive Equilibrium Optimization

Gupta Brij B., Pan Shin-Hung, Gaurav Akshat, Arya Varsha, Alhalabi Wadee, Chui Kwok Tai

[NRF 연계] 한국통신학회 ICT Express Vol.12 No.2 2026.04 pp.324-329

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Modern network security has a great difficulty in cyber attack detection. In this context, this work presents an CNN-LSTM-GRU Model for cyber attack detection. AEO was used to maximize feature selection for the model, therefore lowering unnecessary data while maintaining important attack patterns. With 98% accuracy, the suggested model beats conventional GRU, LSTM, and RNN architectures according to experimental data. Computationally efficient for the proposed model achieves equivalent accuracy to the Transformer model with less number of FLOPs and parameters.

2

Adaptive robust FDI attack detection for cyber?physical? systems with disturbance

Lu Li, Yong Chen, Meng Li, Yuezhi Liu

[NRF 연계] 한국통신학회 ICT Express Vol.9 No.4 2023.08 pp.656-663

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

This paper investigates the problem of attack detection for cyber?physical systems (CPSs) with disturbances, measurement noises, and false data injection (FDI) attacks. A classical linear discrete-time system attack model is constructed and a robust attack detector based on the mixed H_/H is designed. Firstly, a system with an actuator that suffered a malicious attack is modeled. Then, a robust attack detector based on the mixed H_/H is designed in which the H_ index and H index are used to characterize the sensitivity to attacks and robustness to disturbances and measurement noises, respectively. And an adaptive detection threshold with a compensation term is proposed. Besides, the designed robust attack detector enables the attack detection dynamic system to be asymptotically stable and to guarantee the H_/H performance, and the robust attack detector gains are solved from a convex optimization. Finally, the obtained theoretical results are validated through a numerical simulation and a three-area power system simulation.

3

Camp2Vec: Embedding cyber campaign with ATT&CK framework for attack group analysis

Lee Insup, Choi Changhee

[NRF 연계] 한국통신학회 ICT Express Vol.9 No.6 2023.12 pp.1065-1070

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

As the cyberattack subject has expanded from individual to group, attack patterns have become a complicated form of cyber campaigns. Although detecting the attack groups that operated the cyber campaigns is an important issue, complex methods such as deep learning are difficult to use due to the lack of campaign data. This paper proposes Camp2Vec, a lightweight statistics-based embedding for cyber campaigns, enabling attack group detection. The proposed method models a relationship between a campaign and techniques in the ATT&CK® framework as a document and words. Experimental results with expert-labeled datasets prove that Camp2Vec identifies representative attack groups successfully.

4

5,500원

This paper examines methods for protection of government organization’s websites on the focus of 7 7 Cyber Attack in South Korea. On July 7, 2009, twelve websites including the websites of Cheong Wa Dae(the Presidential Office), the National Assembly, the Ministry of National Defense, top internet portals Daum and Naver, and Auction in South Korea and fourteen websites including the websites of the White House and the Department of State in US were attacked by DDoS collectively. The internet sites of South Korea and the abroad important government offices were attacked by DDoS for the first time simultaneously. The affected or zombie computers for themselves could attack the internet sites of important public organizations and agencies. The first attack was that the affected or zombie twenty three thousand PCs in South Korea at 6 p.m. of July 7, 2009 and two thousand PCs abroad helped to attack the websites of important government organizations and agencies. The second attack happened on July 8, 2009. Sixteen thousand zombie PCs were used at the second attack. The third attack was at 6 p.m. of July 9, 2009. Hard diskettes and data in ‘zombie PCs’ which were affected by DDoS were destroyed on July 10, 2009. Zombie PCs with malicious codes exploded for themselves from at least thirty thousand to almost sixty thousand zombie PCs. Methods for protection of government organization’s websites from cyber attacks might be considered as measures for level of citizen, for level of government organization, for state level and for inter‐�state level. Developed countries like US and Japan allocated ten percent of the total budget 10 years ago. South Korea was labeled an internet powerhouse, but Korean government ironically spent only one percent of its entire annual budget on cyber security. Budget for internet security in South Korea should be increased. All owners of virus‐�infected computers should pay immediate attention to cleaning up their operating systems.

5

Cyber Attack 대응 기술 및 표준화

김종현, 김익균

한국컴퓨터통신연구회 OSIA Standards & Technology Review Journal 제27권 제2호 2014.06 pp.76-88

※ 기관로그인 시 무료 이용이 가능합니다.

4,500원

6

A Study on the Real-time Cyber ​​Attack Intrusion Detection Method KCI 등재

Jae-Hyun Choi, Hoo-Jin Lee

한국융합학회 한국융합학회논문지 제9권 제7호 2018.07 pp.55-62

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 다양한 사이버 범죄 위협이 증가하는 추세로 정보시스템을 대상으로 공격하는 사이버 공격에 대해 실시간 탐지 등 최전선에서 초동 대응을 해야 하는 보안관제의 중요성이 높아지고 있다. 보안관제센터, 사이버테러 대응센터, 침해대응센터 등의 이름으로 기관의 관제인원들은 사이버 공격 예방을 위해 많은 노력을 하고 있다. 특히 침해사고 탐지를 위한 방법으로 네트워크 보안장비를 이용하거나 관제시스템을 활용하여 탐지를 하고 있지만 장비 위주의 단순한 패턴기반으로 관제를 하는 방법으로는 침해사고의 예방을 위한 방법으로는 부족하다. 그러므로 보안관제시스템은 지속적으로 고도화 되고 있으며 침해위협에 대한 예방활동으로 탐지방법에 대한 개발과 연구가 활발히 진행되고 있다. 이에 본 논문에서는 기존 침해사고 탐지 방법에 대한 문제점 개선을 위해 주요 구성 모듈의 침해사고 탐지 방법을 정의하고, 성능테스트를 통해 효율적인 보안 관제를 위한 방안을 제시하고 SIEM(Security Information Event Management)을 활용한 관제시스템 고도화를 통하여 효과적인 침해위협 탐지 방법을 연구하고자 한다.

Recently, as the threat of cyber crime increases, the importance of security control to cope with cyber attacks on the information systems in the first place such as real-time detection is increasing. In the name of security control center, cyber ​terror response center and infringement response center, institutional control personnel are making efforts to prevent cyber attacks. Especially, we are detecting infringement accident by using network security equipment or utilizing control system, but it's not enough to prevent infringement accident by just controlling based on device-driven simple patterns. Therefore, the security control system is continuously being upgraded, and the development and research on the detection method are being actively carried out by the prevention activity against the threat of infringement. In this paper, we have defined the method of detecting infringement of major component module in order to improve the problem of existing infringement detection method. Through the performance tests for each module, we propose measures for effective security control and study effective infringement threat detection method by upgrading the control system using Security Information Event Management (SIEM).

7

The Industrial Control System (ICS) is an environment composed of control systems and field devices used to automate industrial processes. With the technological development of the 4th Industrial Revolution, as the connection between the ICS and the external network expands, the risk of exposing cyber threats to the facilities is increasing. Accordingly, cyber-attack response exercises are being implemented around the world using cyber-attack scenarios. A lot of studies are being conducted on evaluating cyber-attack response exercises as well. However, most studies focus only on evaluating the performance of response activities rather than evaluating the cyber-attack scenarios used for these exercises. Our research presents a quantitative evaluation framework to evaluate the quality of cyber-attack scenarios used in cyber-attack response exercises. Our proposed framework consists of a total of 2 stages and determines whether to use the cyber-attack scenario for cyberattack response exercise.

8

The Metaverse is a socially influential platform that offers XR (Extended Reality) users access to multitudinous applications such as a website, a web application, or a desktop program. The handheld controllers, gestures, or voice commands are typically used by the XR-Users to navigate and access these applications. Considering voice commands are the fastest, they are used the most these days. We undertook an attempt to evaluate the security of voice commands for navigating browsers in the Metaverse to access websites. We studied the network analysis trends in depth for virtual environments. We observed URL (Uniform Resource Locator) whitelisting when performing tests on the Oculus Quest 2 voice assistant. We conducted partial network analysis on the network traffic collected during the URL voice command request processing using the OVR (Oculus Virtual Reality) device. With this partial network analysis of the network traffic, we propose a threat model for the OVR voice assistant for processing URLs. We convey, whether voice commands are secure even though they utilize URL whitelisting as a disguise through our research.

9

In the modern society, with the development of Information & Communications Technology (ICT), the cyber threat is also increasing, and to prepare for this, Moving Target Defense (MTD) strategy is widely used to actively protect the Mission-Critical Systems. Although the MTD strategy has shifted the paradigm from passive system defense to active system defense, the indiscriminate use of the MTD strategy has the disadvantage of acting as a large overhead on the system to be protected. To solve this problem, in this paper, we derive the attack surface of the system to be protected using cyber attack information (OpenIOC). Then, based on the derived data, we propose a data visualization engine that can help configure a systematic MTD strategy by linking it with MTD strategy components. Through the proposed data visualization engine, existing and new MTD strategy researchers can configure a more systematic MTD strategy.

10

싸이킷런과 사이버위협 데이터셋을 이용한 사이버 공격 그룹의 분류 KCI 등재

김경신, 이호준, 김성희, 김병익, 나원식, 김동욱, 이정환

중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제8권 제6호 2018.12 pp.165-171

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 IT보안의 화두가 되고 있는 가장 위협적인 공격은 APT공격이다. APT공격에 대한 대응은 인공지능기법을 활용한 대응이외에는 방법이 없다는 것이 현재까지의 결론이다. 여기서는 머신러닝 기법을 활용한 사이버위협 데이터를 분 석하는 방법, 그 중에서도 빅데이터 머신러닝 프레임웍인 Scikit Learn를 활용하여 사이버공격 사례를 수집한 데이터셋을 이용하여 사이버공격을 분석하는 머신러닝 알고리즘을 구현하였다. 이 결과 70%에 육박하는 공격 분류 정확도를 보였다. 이 결과는 향후 보안관제 시스템의 알고리즘으로 발전가능하다.

The most threatening attack that has become a hot topic of recent IT security is APT Attack.. So far, there is no way to respond to APT attacks except by using artificial intelligence techniques. Here, we have implemented a machine learning algorithm for analyzing cyber threat data using machine learning method, using a data set that collects cyber attack cases using Scikit Learn, a big data machine learning framework . The result showed an attack classification accuracy close to 70%. This result can be developed into the algorithm of the security control system in the future.

11

북한의 대남 사이버공격 양상과 행태 : 사이버파워와 강압이론을 통한 분석 KCI 등재

윤태영, 우정민

한국융합보안학회 융합보안논문지 제18권 제1호 2018.03 pp.117-128

※ 기관로그인 시 무료 이용이 가능합니다.

4,300원

본 논문은 주요 국제정치이론을 바탕으로 2009년 들어 지속되어온 북한의 사이버 상에서 대남공격 행태를 분석하여 한국의 정책적 대응방안을 제시하는 것이 목적이다. 이를 위해 본 논문은 국제안보학계에서 최근 주목받는 ‘사이버파워’ 의 행동영역과 특성 및 ‘강압의 역동성’ 모델을 적용하였다. 북한의 사이버공격 유형은 권력기반 잠식, 지도자 리더십 공 격과 음해, 군사작전 방해, 사회불안과 혼란유도 유형으로 분류된다. 사이버파워 유형과 수단 면에서 북한의 GPS 교란, 국방부 서버해킹, EMP 등은 보복·위협성이 강한 하드파워이고, 사이버머니 현금화, 렌섬웨어 등은 소프트웨어를 볼모로 거액의 돈을 강탈하거나 요구하는 점에서 설득·유인의 행동 영역에서 힘으로 분석된다. 북한의 사이버공격은 2차 핵실 험을 기점으로 현실적 제재에 따른 탈출구적 성격을 갖는다. 한국은 북한의 공세적 사이버파워가 방법과 능력에서 변화 하고 있음을 명확히 인식하고, 북한의 행동이 이득보다 감당할 수 없는 손실이 훨씬 더 클 것이라는 결과를 갖게끔 만 드는 것이 중요하다. 이를 위해서는 사이버심리전, EMP공격 대비, 해킹보안의 전문성 강화 등 제도적 보완과 신설을 통 해 공격과 방어가 동시에 이루어지는 사이버보안과 역량을 강화할 필요가 있다.

The purpose of this paper is to analyze the behavior of North Korea's cyber attack against South Korea since 2009 based on major international security theories and suggest South Korea’s policy option. For this purpose, this paper applied the behavioral domain and characteristics of 'cyber power' and ‘coercion dynamics' model, which are attracting attention in international security studies. The types of cyber attacks from North Korea are classified into the following categories: power-based incarceration, leadership attacks and intrusions, military operations interference, and social anxiety and confusion. In terms of types and means of cyber power, North Korean GPS disturbance, the Ministry of Defense server hacking and EMP are hard power with high retaliation and threat and cyber money cashing and ransomware are analyzed by force in the act of persuasion and incentive in the point of robbing or asking for a large amount of money with software pawns. North Korea 's cyber attack has the character of escape from realistic sanctions based on the second nuclear test. It is important for South Korea to clearly recognize that the aggressive cyberpower of North Korea is changing in its methods and capabilities, and to ensure that North Korea's actions result in far greater losses than can be achieved. To do this, it is necessary to strengthen the cyber security and competence to simultaneously attack and defend through institutional supplement and new establishment such as cyber psychological warfare, EMP attack preparation, and enhancement of security expertise against hacking.

12

연합 학습은 데이터 프라이버시 보호에 뛰어남과 동시에 낮은 통신 비용을 달성할 수 있으며, 이를 통해 모델의 학습 데이터 양이 적거나 성능이 낮은 문제를 해결할 수 있다. 본 연구는 사물인터넷 (IoT) 플랫폼 상에 네트워크 공격 탐지 분야에서 활용할 수 있는 탐지 모델의 구조를 제안하고, 연합학습을 통해 기존 모델의 성능을 높이고 학습 시간을 낮추는 등 개선 방법에 대해 제안한다.

13

의료기관 대상의 사이버 공격 시나리오 생성 모형 KCI 등재

노성현, 김태성

한국경영정보학회 경영정보학연구 제26권 제3호 2024.08 pp.143-161

※ 기관로그인 시 무료 이용이 가능합니다.

5,400원

병원과 같은 의료기관의 서비스 중단은 환자를 비롯한 사람의 생명에 영향을 미치게 된다. 이런 특성 때문에 의료기관 측은 공격자의 요구에 응할 가능성이 매우 높아 사이버 공격의 주요 대상이 된다. 최근에는 병원에서 최신 정보 기술의 도입을 확대하면서 사이버 공격이 지속해서 발생하고 있다. 심지어는 사이버 공격에 의한 서비스 마비로 인해 제때 처치를 받지 못한 환자가 사망하는 사건도 일어났다. 더군다나 코로나19 팬데믹 기간에, 의료기관에 대한 사이버 공격 유형이 다변화되거나 빈도가 눈에 띄게 증가했다. 그러나 의료기관 측은 예산 부족 등의 이유로 정보보호 투자에 소극적이며 제대로 방비를 갖추지 못하고 있다. 따라서 본 연구에서는 실제 의료기관에서 발생한 침해사고 사례를 바탕으로 의료기관이 한정된 예산으로도 공격 유형에 따른 보호 조처를 할 수 있도록 공격 시나리오를 생성하는 방법을 예시와 함께 제시한다.

Service disruptions at medical institutions such as hospitals affect the lives of people, including patients. Because of these characteristics, medical institutions are highly likely to comply with attackers' demands, making them prime targets for cyber attacks. Recently, as hospitals expand their adoption of the latest information technology, cyber attacks continue to occur. There was even an incident where a patient who did not receive timely treatment died due to service paralysis caused by a cyber attack. Moreover, during the COVID-19 pandemic, the types of cyber attacks against medical institutions have diversified or their frequency has increased noticeably. However, medical institutions are passive in investing in information security and are not properly prepared for reasons such as lack of budget. Therefore, in this study, based on actual cases of breaches that occurred in medical institutions, we present examples and how to create attack scenarios so that medical institutions can take protective measures according to the type of attack even with a limited budget.

14

산업제어시스템(ICS)는 산업 프로세스를 자동화하기 위해 사용되는 제어시스템과 현장 장치로 구성 된 환경이다. 4차 산업혁명의 기술 발전에 따라 산업제어시스템과 외부 네트워크 간의 연결이 확대되 면서, 해당 시설의 사이버위협 노출 위험이 증가하고 있다. 이에 따라 전 세계적으로 훈련용 사이버공 격 시나리오를 활용하여 사이버공격 훈련 프로그램을 시행하고 있으나, 현존하는 훈련 시나리오는 지 속적으로 진화하는 사이버위협을 반영하지 못하는 한계가 있다. 이에 본 논문은 훈련용 사이버공격 시 나리오의 품질을 평가하는 평가 방법론을 제시한다. 해당 방법론은 총 3단계로 구성되어 있으며, 이를 통해 사이버공격 대응 훈련에 대한 훈련용 사이버공격 시나리오의 활용 여부를 도출한다.

15

지능형 사이버 공격 경로 분석 방법에 관한 연구 KCI 등재

김남욱, 이동규, 엄정호

한국융합보안학회 융합보안논문지 제21권 제1호 2021.03 pp.93-100

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

지능형 사이버 공격으로 인한 피해는 시스템 운영 중단과 정보 유출뿐만 아니라 엄청난 규모의 경제적 손실을 동반 한다. 최근 사이버 공격은 공격 목표가 뚜렷하며, 고도화된 공격 도구와 기법을 활용하여 정확하게 공격 대상으로 침투 한다. 이러한 지능적인 사이버 공격으로 인한 피해를 최소화하기 위해서는 사이버 공격이 공격 대상의 핵심 시스템까지 침입하지 못하도록 공격 초기 또는 과정에서 차단해야 한다. 최근에는 빅데이터나 인공지능 기술을 활용하여 사이버 공 격 경로를 예측하고 위험 수준을 분석하는 보안 기술들이 연구되고 있다. 본 논문에서는 자동화 사이버 공격 경로 예측 시스템 개발을 위한 기초 메커니즘으로 공격 트리와 RFI 기법을 활용한 사이버 공격 경로 분석 방법을 제안한다. 공격 트리를 활용하여 공격 경로를 가시화하고 각 공격 단계에서 RFI 기법을 이용하여 다음 단계로 이동할 수 있는 경로를 판단한다. 향후에 제안한 방법을 기반으로 빅데이터와 딥러닝 기술을 활용한 자동화된 사이버 공격 경로 예측 시스템의 메커니즘으로 활용할 수 있다.

Damage caused by intelligent cyber attacks not only disrupts system operations and leaks information, but also entails massive economic damage. Recently, cyber attacks have a distinct goal and use advanced attack tools and techniques to accurately infiltrate the target. In order to minimize the damage caused by such an intelligent cyber attack, it is necessary to block the cyber attack at the beginning or during the attack to prevent it from invading the target's core system. Recently, technologies for predicting cyber attack paths and analyzing risk level of cyber attack using big data or artificial intelligence technologies are being studied. In this paper, a cyber attack path analysis method using attack tree and RFI is proposed as a basic algorithm for the development of an automated cyber attack path prediction system. The attack path is visualized using the attack tree, and the priority of the path that can move to the next step is determined using the RFI technique in each attack step. Based on the proposed mechanism, it can contribute to the development of an automated cyber attack path prediction system using big data and deep learning technology.

16

인공지능의 학습 데이터 부족 문제와 사생활 침해 문제를 해결하기 위해 고안된 연합 학습 (FL)은 여러 클라이언트가 학습에 참가하는 특징으로 데이터 긴밀성과 효율적인 데이터 처리를 가능케 한다. 본 연구는 연합 학습을 사물인터넷 (IoT)과 융합하여 인프라를 설계하고 구축하였다. 또한 융합한 인프라를 통해 네트워크 보안이라는 도메인에 주목하여 사이버 공격 탐지 모델을 구상하고, 성능 측정을 통해 연합 학습의 적용 범위를 확장한다.

17

북한 사이버공격에 대한 대응방안에 관한 연구 KCI 등재

정영도, 정기석

한국융합보안학회 융합보안논문지 제16권 제6호 제1호 2016.10 pp.43-50

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

북한이 우리 사회의 취약한 전산망에 대한 충분한 사이버 공격능력을 갖추고 있어 다양한 대규모의 사이버 공격을 시도할 것으로 예상된다. 북한의 사이버전 수준은 세계 최고수준으로 알려져 있다. 사이버 요원의 수도 지속적으로 증가 하고 있다. 최근 북한의 사이버공격은 수법과 대상을 가리지 않는 전방위적으로 행해지고 있다. 그러나 지금까지의 북한 사이버공격은 실질적인 공격이라기보다는 탐색의 성격이 강하다. 남한이 얼마나 빨리 문제를 발견하고 복구하는지를 알 아보기 위한 목적이었다고 볼 수 있다. 하지만 앞으로는 막대한 실질적 피해를 주는 사이버공격을 자행할 개연성이 높 다. 주요 교통·금융·에너지시설 등의 국가기반시설에 대한 공격이 발생할 경우 그 피해규모는 상상을 초월할 것이므로 이에 대한 대책이 필요하다. 따라서 본 논문에서는 최근 북한 사이버공격의 특징을 살펴보고 대응 방안으로 사이버테러 방지법제정, 대응모의훈련실시, 민관협력체제 구축, 사이버보안 인프라 확대 등을 제시하고자 한다.

As North Korea has a sufficient ability to attack our society’s vulnerable computer network, various large-scale cyber attacks are expected to be tried. North Korea’s cyber military strength is known a world-class level. The number of its cyber agents is increasing consistently. Recently North Korea’s cyber attack has been made regardless of trick and target. But up to now North Korea’s cyber attack is more of an exploration than a real attack. Its purpose was to check how fast Korea found a problem and recovered from it. In future, cyber attack that damages substantially is highly probable. In case of an attack against national infrastructure like traffic, financial and energy services, the extent of the damage will be great beyond imagination. In this paper, characteristics of recent North Korea’s cyber attack is addressed in depth and countermeasures such as the enactment of cyber terror prevention law, simulation training enforcement, private and public cooperation system construction, cyber security infrastructure expansion, etc. are proposed.

18

사이버공격의 정량적 피해평가를 통한 공세적 대응규모 산정 KCI 등재

홍병진, 임재성, 김완주, 조재명

한국융합보안학회 융합보안논문지 제17권 제4호 2017.10 pp.17-30

※ 기관로그인 시 무료 이용이 가능합니다.

4,600원

우리사회와 정부에 대한 다양한 사이버 공격이 지속적으로 이루어지고 있으며 수시로 그 사례 및 피해가 발표되고 있다. 그리고 사이버공격의 영역 또한 사이버공간에 국한되는 것이 아니라 물리적 영역으로 확대되어 영향을 미치고 있다. 군사적영역에서는 적의 물리적 공격에 대해 비례성을 갖고 대응한다는 원칙을 수립하고 시행하고 있다. 영역이 확대되고 있는 사이버전에서도 이러한 비례성 원칙이 필요할 것으로 판단되며, 실제 적용하기 위해서는 사이버공격에 대한 정량적, 정성적 대응기준을 가지고 있어야 할 것이다. 그러나 사이버공격의 특성상 정확한 피해평가가 쉽지 않아 비례성이 모호하며 비례성 원칙으로 대응하는 것도 어려울 것이다. 이에 본 연구에서는 시나리오를 기반으로 사이버공격이 조직이나 시스템에 미치는 영향을Gorden-Lobe 모델과 시큐리티 스코어링 기법을 이용하여, 사이버 공격 피해를 정량적․정성적으로 평가하여 피해규모를 산출하였다. 산출된 결과는 사이버공격에 대한 공세적으로 대응하기 위한 적절한 수준과 기준으로 제공할 것으로 기대한다.

Various cyber attacks against our society and the government are continuing, and cases and damages are r eported from time to time. And the area of cyber attack is not limited to cyberspace, but it is expanding into physical domain and affecting it. In the military arena, we have established and implemented the principle of r esponding proportionally to enemy physical attacks. This proportionality principle is also required in the versio n where the region is expanding. In order to apply it, it is necessary to have a quantitative and qualitative co untermeasure against cyber attack. However, due to the nature of cyber attacks, it is not easy to assess the d amage accurately and it is difficult to respond to the proportionality principle and the proportional nature. In t his study, we calculated the damage scale by quantitatively and qualitatively evaluating the cyber attack dama ge using the Gorden-Lobe model and the security scoring technique based on the scenario. It is expected that the calculated results will be provided as appropriate level and criterion to counteract cyber attack.

19

공격키워드 사전 및 TF-IDF를 적용한 침입탐지 정탐률 향상 연구 KCI 등재

김종관, 김명수

한국융합보안학회 융합보안논문지 제22권 제2호 2022.06 pp.9-19

※ 기관로그인 시 무료 이용이 가능합니다.

4,200원

최근, 디지털전환의 확대로 사이버공격의 위협에 더욱 더 노출되고 있으며, 각 기관 및 기업은 공격이 유입되는 것 을 막기 위해 시그니처 기반의 침입차단시스템을 네트워크 가장 앞단에 운영중에 있다. 그러나, 관련된 ICT시스템에 적절한 서비스를 제공하기 위해 엄격한 차단규칙을 적용할 수 없어 많은 오이벤트가 발생되고, 운영효율이 저하되고 있다. 따라서, 공격탐지 정확도 향상을 위하여 인공지능을 이용한 많은 연구과제가 수행되고 있다. 대부분의 논문은 정 해진 연구용 데이터셋을 이용하여 수행하였지만, 실제 네트워크에서는 연구용 학습데이터셋과는 다른 로그를 이용해야 만 하기 때문에 실제 시스템에서는 사용사례는 많지 않다. 본 논문에서는 실제 시스템에서 수집한 보안이벤트 로그에 대하여 주요 공격키워드를 분류하고, 주요 키워드별로 가중치를 부과, TF-IDF를 이용하여 유사도 검사를 수행후 실제 공격여부를 판단하는 기법에 대하여 제안하고자 한다.

As the expansion of digital transformation, we are more exposed to the threat of cyber attacks, and many institution or company is operating a signature-based intrusion prevention system at the forefront of the network to prevent the inflow of attacks. However, in order to provide appropriate services to the related ICT system, strict blocking rules cannot be applied, causing many false events and lowering operational efficiency. Therefore, many research projects using artificial intelligence are being performed to improve attack detection accuracy. Most researches were performed using a specific research data set which cannot be seen in real network, so it was impossible to use in the actual system. In this paper, we propose a technique for classifying major attack keywords in the security event log collected from the actual system, assigning a weight to each key keyword, and then performing a similarity check using TF-IDF to determine whether an actual attack has occurred.

20

북한의 비대칭 전략 - ‘사이버 기습공격’에 대한 대책 연구 KCI 등재후보

권문택

한국융합보안학회 융합보안논문지 제10권 제4호 2010.12 pp.83-91

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

본 연구는 한반도내에서 발생 가능한 비대칭 전략으로서의 ‘사이버 기습공격’의 발생 가능성에 대해 분석하고 이에 대한 정책적 대책을 제시하기 위해 작성한 것이다. 최근 발생하고 있는 이 란, 중국 등에서 발생한 ‘Stuxnet’ 사이버 기습공격 피해 사례로 볼 때 만일 북한이 남한의 인프 라 시설을 공격한다면 남한 사회에 큰 혼란과 피해를 줄 수 있을 것이다. 최근 발생한 연평도 기습도발 사건 이후 계속적인 도발 위협을 하고 있는 북한의 태도로 볼 때 ‘Stuxnet’과 같은 사 이버공격을 감행할 개연성이 높기 때문에 이에 대한 정책적 대책을 제시하였다. 주요 대책은 1) 독립된 중앙집권적 정부통합조직 신설, 2) 특수대학 설립으로 사이버전 전문인력 양성, 3) 예산 증액 및 전문인력 관리체계 개선이다.

Information security is a critical issue for national defense. This paper provides a result of a study on the countermeasures to the North Korean Asymmetric Strategy-‘Cyber Surprise Attack’. After the attack on Yeonpyeong island, the North Korea threatened there will be more surprise attack to the South Korea. Based on the analysis of ‘Stuxnet’ cyber attack to Iran and China, the North Korean surprise attack may be ‘Stuxnet’ class cyber attack. This paper several strategic countermeasures in order to overcome the anticipated the North Korean cyber surprise attack.

 
1 2 3 4
페이지 저장